CVE-2026-25611Disclosure

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

A series of specifically crafted, unauthenticated messages can exhaust available memory and crash a MongoDB server.

0.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-405

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

DECLINING

Threat summary

  • Patch or workaround signal is available
  • 21 mentions across 10 observed days
  • Momentum state: declining

What's happening

  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 17 signals
  • Disclosure: 12 classified signals
  • General: 4 classified signals
  • Peaked 6d ago at 10 mentions (2026-03-05); latest day: 1
  • 21 total mentions across 10 days

Deep dive

Activity timeline21 mentions / 10d
035810Mentions · 2026-02-10: 1Mentions · 2026-02-11: 1Mentions · 2026-02-16: 1Mentions · 2026-03-05: 10Mentions · 2026-03-06: 2Mentions · 2026-03-07: 1Mentions · 2026-03-08: 2Mentions · 2026-03-09: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 1Patch / Workaround · 2026-03-05: 3Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-09: 1Technical Details · 2026-02-10: 1Technical Details · 2026-02-11: 1Technical Details · 2026-03-05: 9Technical Details · 2026-03-06: 2Technical Details · 2026-03-08: 1Technical Details · 2026-03-09: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 102-1002-1102-1603-0503-0603-0703-0803-0903-1003-11
Signal classification3 categories
Disclosure
1257.1%
Patch
523.8%
General
419.0%
Referenced assets15 URLs
Classification over time
DateTotalLabels
2026-02-101
General1
2026-02-111
Disclosure1
2026-02-161
General1
2026-03-0510
Disclosure6General1Patch3
2026-03-062
Disclosure2
2026-03-071
Patch1
2026-03-082
Disclosure1General1
2026-03-091
Patch1
2026-03-101
Disclosure1
2026-03-111
Disclosure1
Full discourse20 posts
  • Cyber Security News@The_Cyber_News
    Disclosure

    ⚠️ New MongoDB Vulnerability Lets Hackers Crash Any MongoDB Server Source: https://cybersecuritynews.com/mongodb-vulnerability-crash-server/ A high-severity vulnerability, CVE-2026-25611 (CVSS 7.5), has been discovered in MongoDB, allowing unauthenticated attackers to crash exposed servers using minimal bandwidth. It affects all MongoDB versions where compression is enabled (v3.4+, on by default since v3.6), including MongoDB Atlas. An attacker can send a tiny 47KB zlib-compressed packet while claiming an uncompressed size of 48MB to crash the server. #cybersecuritynews

    Post summary

    A newly discovered high‑severity vulnerability (CVE‑2026‑25611) in MongoDB allows unauthenticated attackers to crash any server with a crafted compressed packet. No active exploitation or patch information is reported.

    5381133265.4K
    50.1K followersView on X
  • にゃん☆たく/takumi.a@taku888infinity
    Disclosure

    New MongoDB Vulnerability Lets Hackers Crash Any MongoDB Server https://cybersecuritynews.com/mongodb-vulnerability-crash-server/ 『(直訳)MongoDB に重大度の高い脆弱性 CVE-2026-25611 (CVSS 7.5) が発見され、認証されていない攻撃者が最小限の帯域幅を使用して公開されたサーバーをクラッシュさせる可能性があります。Cato CTRL によると、これは MongoDB Atlas を含む、圧縮が有効になっているすべての MongoDB バージョン (v3.4+、v3.6 以降はデフォルトで有効) に影響します。』

    Post summary

    This article announces a new denial‑of‑service vulnerability (CVE‑2026‑25611) in MongoDB that allows unauthenticated attackers to crash any server with compression enabled, but no proof‑of‑concept, exploit, or patch details are disclosed.

    010831.2K
    11.3K followersView on X
  • Zyberwalls@ZyberWallS
    Disclosure

    🚨 New MongoDB Vulnerability Discovered A tiny 47KB packet can force a MongoDB server to allocate 48MB of memory. Just a few connections → database crash. No authentication required. CVE-2026-25611 explained 👇 https://www.zyberwalls.com/2026/03/mongodb-cve-2026-25611-dos-memory-exhaustion-analysis.html #CyberSecurity #CVE #IndiaVsNewZealand

    Post summary

    The post announces a new MongoDB vulnerability (CVE‑2026‑25611) that forces a server to allocate excessive memory via a small packet, leading to a crash, and directs readers to a detailed analysis.

    0102067
    9 followersView on X
  • Zyberwalls@ZyberWallS
    Patch

    New MongoDB Crisis: CVE-2026-25611 🚨 Patched versions:✅ 8.2.4 ✅ 8.0.18 ✅ 7.0.29 Immediate Fix: Disable network compression if you can’t patch yet! 🛡️ Full Analysis https://www.zyberwalls.com/2026/03/mongodb-cve-2026-25611-dos-memory-exhaustion-analysis.html #MongoDB #CyberSecurity #CVE202625611 #InfoSec #ZyberWalls

    Post summary

    The post alerts on CVE‑2026‑25611, lists patched MongoDB releases, recommends disabling network compression as an interim fix, and links to a detailed analysis.

    0101043
    9 followersView on X
  • VulnTracker@vuln_tracker
    Disclosure

    Thanks for sharing! Another reminder that availability bugs can be just as damaging as data breaches. The newly reported MongoDB vulnerability (CVE-2026-25611) allows attackers to crash exposed servers using a small crafted compressed packet. We’ve added it to http://Vulntracker.io so teams can keep an eye on it. https://vulntracker.io/cves/CVE-2026-25611

    Post summary

    The post announces the newly reported MongoDB CVE-2026-25611, noting it causes server crashes via crafted compressed packets, but offers no PoC, exploit, patch, or active exploitation details.

    01010132
    390 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    MongoDB flaw CVE-2026-25611 lets unauthenticated attackers crash servers with little traffic. Affects v3.4+ with compression, including Atlas; Shodan shows 207k exposed. #vulnerability https://threatcluster.io/cluster/critical-mongodb-vulnerability-allows-server-crashes-by-unau-35ddb5d7

    Post summary

    A newly disclosed MongoDB flaw, CVE-2026-25611, lets unauthenticated users crash servers with minimal traffic, impacting v3.4+ and Atlas; over 200k exposed instances are noted by Shodan.

    1001040
    91 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    MongoDB の DoS 脆弱性 CVE-2026-25611 が FIX:インターネット上の 207,000 インスタンスに影響 https://iototsecnews.jp/2026/03/05/new-mongodb-vulnerability-allows-attackers-to-crash-servers-exposing-critical-data/ MongoDB の通信プロトコル (OP_COMPRESSED) に、サーバを強制停止させる深刻な DoS 脆弱性 CVE-2026-25611 (CVSS 8.7) が発見されました。この問題の原因は、データの正しさを確認する前に、プログラムがメモリを確保してしまうという、処理順序の不備にあります。 MongoDB が圧縮されたメッセージを受け取ると、パケットヘッダにある展開後のサイズが読み取られます。脆弱なバージョンでは、このサイズの妥当性を検証する前に、指定された通りの巨大なメモリ領域を確保されます。この欠陥を突く攻撃者は、わずか 47KB の小さなパケットで “48MB のメモリを確保せよ” という偽の命令を送り、サーバのメモリを枯渇させます。 この攻撃で懸念されるのは、ログインが必要になる前の段階で実行できるため、インターネットに公開されている、すべてのサーバに対して攻撃が可能なことです。ご利用のチームは、ご注意ください。よろしければ、MongoDB での検索結果も、ご参照ください。 #CVE202625611 #MongoDB #Vulnerability

    Post summary

    A newly disclosed DoS vulnerability (CVE‑2026‑25611) in MongoDB’s OP_COMPRESSED protocol can trigger memory exhaustion with a 47KB packet, but no PoC, exploit script, patch, or evidence of active exploitation has been reported.

    01000139
    484 followersView on X
  • Emerson Yougbaré@emzrsxn
    Patch

    64 Mo de trafic depuis une connexion domestique ordinaire suffisent à faire tomber une base MongoDB de 64 Go en moins d'une minute. C'est le résultat des tests menés par Cato CTRL sur CVE-2026-25611, une vulnérabilité de sévérité élevée (CVSS 7.5) publiée le 5 mars 2026. Elle affecte toutes les versions de MongoDB depuis la 3.4, y compris MongoDB Atlas, soit par défaut la quasi-totalité des déploiements actifs. Selon Shodan, plus de 207 000 instances MongoDB sont actuellement exposées sur Internet. La faille se trouve dans le mécanisme de compression des messages réseau de MongoDB, appelé OP_COMPRESSED. Lorsqu'un serveur reçoit un message compressé, il alloue de la mémoire en se basant sur la taille décompressée annoncée dans le message, avant même de vérifier la taille réelle. Un attaquant peut envoyer un paquet de 47 Ko en prétendant qu'il pèse 48 Mo une fois décompressé. Le serveur alloue 48 Mo sans questionner. Rapport d'amplification mémoire : 1 027 pour 1. En ouvrant plusieurs connexions simultanées sur ce principe, l'attaquant épuise rapidement la RAM disponible. Un serveur avec 512 Mo de mémoire s'effondre en deux secondes avec seulement 10 connexions. Une instance de 1 Go tombe en trois secondes avec 25 connexions. Et même un déploiement enterprise de 64 Go peut être mis hors ligne en moins d'une minute, sans authentification préalable, sans exploit sophistiqué, et sans générer de trafic notable. La correction est disponible dans les versions MongoDB 8.2.4, 8.0.18 et 7.0.29. Si la mise à jour immédiate n'est pas possible, Cato CTRL recommande de désactiver la compression réseau avec l'option --networkMessageCompressors=disabled, et de restreindre l'accès au port 27017 aux seules adresses de confiance. Ce type de vulnérabilité est particulièrement préoccupant pour les PME parce que MongoDB est l'une des bases de données les plus utilisées dans les applications web modernes, et qu'elle est fréquemment déployée avec une configuration par défaut, sans restriction d'accès réseau. Une interruption de service non planifiée sur une base de production peut suffire à mettre une activité à l'arrêt le temps de comprendre ce qui s'est passé. Source : Cato CTRL / Cybersecurity News, 5 mars 2026 — lien en commentaire. #Cybersécurité #MongoDB #Vulnérabilité #DoS #GestionDesRisques #PME #GRC #VeilleInformationnelle

    Post summary

    The article announces a high‑severity MongoDB DoS vulnerability (CVE‑2026‑25611), details its memory‑allocation flaw, provides patch and mitigation guidance, but does not claim active exploitation or supply exploit code.

    1000042
    1.6K followersView on X
  • Cybersecurity News Everyday@TweetThreatNews
    Patch

    A critical MongoDB vulnerability (CVE-2026-25611) in OP_COMPRESSED protocol allows unauthenticated attackers to trigger massive memory allocation and crash servers. Patch and limit exposure advised. #DatabaseSecurity #MongoDBFlaw #USA https://ift.tt/WvmVtJT

    Post summary

    A critical MongoDB vulnerability (CVE-2026-25611) permits unauthenticated users to cause a memory allocation crash, and a patch is recommended.

    00010118
    3.7K followersView on X
  • CVETrends@CVEShield
    General

    Top 5 Trending CVEs: 1 - CVE-2024-23222 2 - CVE-2026-22719 3 - CVE-2026-25611 4 - CVE-2025-38617 5 - CVE-2026-21902 #cve #cvetrends #cveshield #cybersecurity https://www.cveshield.com/dashboard

    Post summary

    The tweet merely lists five trending CVE IDs without providing any additional context or information.

    00010232
    1.7K followersView on X
  • CERT-PY@CERTpy
    General

    ⚠️ Vulnerabilidades en productos MongoDB ❗ CVE-2026-25611 ❗ CVE-2026-1848 ➡️ Más info: https://www.cert.gov.py/vulnerabilidades-en-productos-mongodb/ https://t.co/VjiO5cn3qZ

    Post summary

    The tweet lists two MongoDB CVEs and links to external pages for more information, but does not provide PoC, exploit, or mitigation details.

    00001115
    6.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25611 MongoDB Denial of Service via Unauthenticated Memory Exhaustion Attack https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25611

    Post summary

    MongoDB’s CVE‑2026‑25611 is a denial‑of‑service vulnerability that allows unauthenticated memory‑exhaustion attacks, but no PoC, exploit, or patch is disclosed in the text.

    0001093
    4.0K followersView on X
  • Jamaica Cyber Incident Response Team (JaCIRT)@cirtgovjm
    Disclosure

    🚨 Security Advisory: Critical MongoDB Vulnerability A critical vulnerability (CVE-2026-25611) has been identified in MongoDB’s wire protocol compression mechanism (OP_COMPRESSED) with a CVSS score of 7.5. Click here for more information 👇 https://cirt.gov.jm/advisory/critical-mongodb-vulnerability-cve-2026-25611-enables-server-crashes-malformed-compressed https://t.co/oAs964CEq5

    Post summary

    The advisory announces a critical MongoDB vulnerability affecting the OP_COMPRESSED wire protocol, noting its CVSS score but providing no PoC, exploit code, or patch details.

    00000135
    1.1K followersView on X
  • Zyberwalls@ZyberWallS
    General

    @The_Cyber_News Full breakdown of CVE-2026-25611 👇 https://www.zyberwalls.com/2026/03/mongodb-cve-2026-25611-dos-memory-exhaustion-analysis.html

    Post summary

    The tweet links to a full breakdown article on CVE-2026-25611 but offers no additional technical or exploitation details.

    0000029
    9 followersView on X
  • Cato CTRL@CatoCTRL
    Patch

    Internet-exposed MongoDB servers can be crashed. 🚨 Cato CTRL found a vuln putting 210,000+ instances at risk, letting attackers take databases offline in seconds, even in enterprise environments. A fix is available. Patch now. ⚠️ https://www.catonetworks.com/blog/cato-ctrl-new-mongodb-vulnerability-cve-2026-25611/?utm_campaign=CatoCTRL&utm_source=twitter&utm_medium=social https://t.co/qOiNOUatx6

    Post summary

    CatoCTRL announced CVE-2026-25611, which can crash exposed MongoDB servers; a patch is available that administrators should apply immediately.

    0000043
    132 followersView on X
  • The NoSQL Nerd@NoSQLNerd
    Disclosure

    Urgent: New MongoDB crash vulnerability (CVE-2026-25611). If you run MongoDB v3.4+ this writeup shows how attackers can force a crash and which versions are impacted. Read the analysis and mitigation steps: https://cybersecuritynews.com/mongodb-vulnerability-crash-server/

    Post summary

    The tweet announces a new MongoDB crash vulnerability (CVE-2026-25611) affecting v3.4+, offers an analysis and mitigation steps, but does not provide PoC, exploit, or patch details.

    0000043
    6 followersView on X
  • 96mHKy@96m_h16634
    Disclosure

    @The_Cyber_News Xiaoxiao:“⚠️ MongoDB 新漏洞让黑客能够瘫痪任何 MongoDB 服务器 MongoDB 中发现了一个高危漏洞 CVE-2026-25611 (CVSS 7.5),该漏洞允许未经身份验证的攻击者利用极小的带宽瘫痪暴露的服务器。 所有启用压缩功能的 MongoDB 版本(v3.4 及更高版本,v3.6 及更高版本默认启用压缩)均受到影响,

    Post summary

    The post announces a high‑severity, unauthenticated MongoDB vulnerability (CVE-2026-25611) that can cause servers to crash via compression features, affecting all V3.4+ deployments with compression enabled.

    0000085
    73 followersView on X
  • Emerson Yougbaré@emzrsxn
    Disclosure

    https://www.catonetworks.com/blog/cato-ctrl-new-mongodb-vulnerability-cve-2026-25611/

    Post summary

    The blog reports a new MongoDB vulnerability (CVE‑2026‑25611) with technical details but no evidence of exploitation, PoC, or patch information.

    0000037
    1.6K followersView on X
  • kantan.news@KantanNewsX
    Patch

    Saniyeler içinde MongoDB sunucularını çökertebilen CVE-2026-25611 kodlu kritik bir açık keşfedildi. Dünya genelinde 207 binden fazla sistem risk altında. Hizmet kesintisi yaşamamak için acil yama yapmanız tavsiye ediliyor. Haberin detayı: https://kantan.news/x_article.php?slug=kritik-mongodb-a-korsanlar-sunucular-saniyeler-inde-kertiyor

    Post summary

    A critical CVE-2026-25611 vulnerability in MongoDB can crash servers in seconds; an immediate patch is strongly advised to protect the 207k+ affected systems.

    0000090
    900 followersView on X
  • Vivek | ThreatIntel@VivekIntel
    Disclosure

    High-severity MongoDB vulnerability (CVE-2026-25611) allows instant server crashes Researchers from Cato CTRL disclosed a pre-authentication flaw in MongoDB’s OP_COMPRESSED handling that can allow attackers to crash servers with minimal traffic. The issue occurs because MongoDB allocates ~48MB of memory per connection before validating decompression parameters. By sending crafted packets (~47KB) with manipulated uncompressedSize values, attackers can trigger rapid memory exhaustion. With enough concurrent connections, even large deployments can experience out-of-memory kills and service disruption. The exposure is amplified by default compression settings and internet-facing instances. Source: https://www.catonetworks.com/blog/cato-ctrl-new-mongodb-vulnerability-cve-2026-25611/ #CyberSecurity #CVE #MongoDB #ThreatIntel

    Post summary

    Researchers from Cato CTRL disclosed a pre‑authentication MongoDB flaw that allows attackers to crash servers via crafted OP_COMPRESSED packets, causing rapid memory exhaustion and out‑of‑memory kills.

    0000059
    166 followersView on X

Explore more